External Secrets Operator 1.2.1 closes eight Go and go-git security flaws
Red Hat’s Important-rated update fixes remotely triggerable denial-of-service paths, a template injection flaw and a worktree escape risk.
Red Hat has released External Secrets Operator for Red Hat OpenShift 1.2.1 as an Important-rated security update. The advisory lists eight fixes: CVE-2026-33818, CVE-2026-41178, CVE-2026-56852, CVE-2026-56853, CVE-2026-56858, CVE-2026-56860, CVE-2026-56862 and CVE-2026-71556.
What changed
Most of the set closes availability weaknesses in the Go runtime and libraries used by the Operator. Red Hat describes remotely triggerable denial-of-service paths involving deeply nested ASN.1 input, oversized OpenTelemetry baggage headers, invalid UTF-8, unencrypted HTTP/2 connection prefaces, relative URLs with many parent-directory segments and repeated TLS KeyUpdate messages.
Two fixes have different impact. CVE-2026-56858 addresses an html/template parsing flaw that can permit arbitrary content injection and cross-site scripting when an application renders untrusted input. CVE-2026-71556 fixes go-git worktree operations that followed symbolic links outside the intended repository boundary; exploitation requires cloning an attacker-controlled repository and then performing checkout, status or add operations.
The aggregate advisory is Important rather than Critical, and Red Hat does not say these flaws are being exploited. The practical reason to update is the concentration of remotely reachable resource-exhaustion conditions in a cluster-wide service that fetches and refreshes secrets from external providers.
Who is affected
The update applies to the supported External Secrets Operator for Red Hat OpenShift. The Operator manages the external-secrets application across the cluster and integrates providers including AWS Secrets Manager, HashiCorp Vault, Google Secret Manager, Azure Key Vault and IBM Cloud Secrets Manager.
Exposure varies by component and configuration. The go-git issue specifically depends on processing an untrusted repository, while the network denial-of-service flaws depend on affected listeners receiving attacker-controlled input.
Update and verify
Red Hat says the default Automatic Operator Lifecycle Manager approval policy upgrades the Operator when a new version becomes available. Clusters changed to Manual approval require an administrator to approve the upgrade.
After approval, verify the result rather than relying only on the catalog notification. In the OpenShift web console, go to Ecosystem → Installed Operators and confirm that External Secrets Operator reports Succeeded in the external-secrets-operator namespace. From the CLI, inspect the subscription, installed ClusterServiceVersion and controller pod:
oc get subscription -n external-secrets-operator
oc get csv -n external-secrets-operator
oc get pods -n external-secrets-operator
The CSV should show version 1.2.1 in the Succeeded phase, and the controller pod should be Running. If an update cannot be applied immediately, Red Hat’s CVE guidance for CVE-2026-71556 is to avoid cloning or running worktree operations against untrusted repositories; Red Hat lists no generally suitable mitigation for CVE-2026-56852.
sources
- RHSA-2026:66363 — External Secrets Operator for Red Hat OpenShift 1.2.1access.redhat.com
- External Secrets Operator for Red Hat OpenShift documentationdocs.redhat.com
- CVE-2026-33818 — Go ASN.1 stack-exhaustion denial of serviceaccess.redhat.com
- CVE-2026-41178 — OpenTelemetry-Go baggage-header denial of serviceaccess.redhat.com
- CVE-2026-56852 — Go x/text invalid UTF-8 denial of serviceaccess.redhat.com
- CVE-2026-56858 — Go html/template content injectionaccess.redhat.com
- CVE-2026-56862 — Go TLS KeyUpdate denial of serviceaccess.redhat.com
- CVE-2026-71556 — go-git worktree symlink boundary escapeaccess.redhat.com
comments · 0